Streamlining Vulnerability Research with the idalib Rust Bindings for IDA 9.2 - HN Security
https://ift.tt/ZkU5dEl
Submitted October 14, 2025 at 01:57PM by 0xdea
via reddit https://ift.tt/Hq0lSmv
https://ift.tt/ZkU5dEl
Submitted October 14, 2025 at 01:57PM by 0xdea
via reddit https://ift.tt/Hq0lSmv
HN Security
Streamlining Vulnerability Research with the idalib Rust Bindings for IDA 9.2 - HN Security
HN Security's Technical Director Marco Ivaldi walks through using idalib's Rust bindings with IDA 9.2 to streamline vulnerability research.
Intents Android (1/2) : fonctionnement, sécurité et exemples d'attaques
https://ift.tt/xfCGv6y
Submitted October 14, 2025 at 04:58PM by MobetaSec
via reddit https://ift.tt/B3Xgpyu
https://ift.tt/xfCGv6y
Submitted October 14, 2025 at 04:58PM by MobetaSec
via reddit https://ift.tt/B3Xgpyu
Mobeta
Intents Android (1/2) : fonctionnement, sécurité et exemples d'attaques | Mobeta
Les Intents Android mal configurés peuvent exposer vos données. Découvrez comment éviter l’intent hijacking et sécuriser vos applications.
BombShell: UEFI shell vulnerabilities allow attackers to bypass Secure Boot on Framework Devices
https://ift.tt/5dUKuMI
Submitted October 14, 2025 at 11:52PM by Titokhan
via reddit https://ift.tt/Vm1CBhJ
https://ift.tt/5dUKuMI
Submitted October 14, 2025 at 11:52PM by Titokhan
via reddit https://ift.tt/Vm1CBhJ
Eclypsium | Supply Chain Security for the Modern Enterprise
BombShell: The Signed Backdoor Hiding in Plain Sight on Framework Devices
Eclypsium researchers have discovered UEFI shells, authorized via Secure Boot, on Framework laptops. The UEFI shells contain capabilities that allow attackers to bypass Secure Boot on roughly 200,000 affected Framework laptops and desktops.
MCP Snitch - The MCP Security Tool You Probably Need
https://ift.tt/ynvW7Uz
Submitted October 15, 2025 at 02:03AM by ok_bye_now_
via reddit https://ift.tt/DOd0PsZ
https://ift.tt/ynvW7Uz
Submitted October 15, 2025 at 02:03AM by ok_bye_now_
via reddit https://ift.tt/DOd0PsZ
www.adversis.io
The MCP Security Tool You Probably Need - MCP Snitch
The Model Context Protocol (MCP) has rapidly emerged as the standard for connecting AI agents to external tools and services. However, as the recent GitHub MCP vulnerability demonstrated, the protocol's power comes with significant security challenges. Malicious…
MORPHEUS – An AI code security analyzer that learns new vulnerabilities on its own
https://ift.tt/JCzHDpu
Submitted October 15, 2025 at 03:57AM by Far_Improvement_9437
via reddit https://ift.tt/IkvJ9hi
https://ift.tt/JCzHDpu
Submitted October 15, 2025 at 03:57AM by Far_Improvement_9437
via reddit https://ift.tt/IkvJ9hi
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit – Kyntra Blog
https://ift.tt/q5Bg8Ut
Submitted October 15, 2025 at 07:17PM by rkhunter_
via reddit https://ift.tt/Uqurk25
https://ift.tt/q5Bg8Ut
Submitted October 15, 2025 at 07:17PM by rkhunter_
via reddit https://ift.tt/Uqurk25
blog.kyntra.io
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit – Kyntra Blog
Deep dive into a modern stealth Linux kernel rootkit with advanced evasion and persistence techniques
yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242) - watchTowr Labs
https://ift.tt/71rZjNy
Submitted October 16, 2025 at 03:36PM by dx7r__
via reddit https://ift.tt/HFXSuMT
https://ift.tt/71rZjNy
Submitted October 16, 2025 at 03:36PM by dx7r__
via reddit https://ift.tt/HFXSuMT
watchTowr Labs
yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242)
Note from editor: Before we begin, a big welcome to McCaulay Hudson, the newest member of the watchTowr Labs team with his inaugural blog post! Welcome to the mayhem, McCaulay!
Today is the 8th of November 1996, and we’re thrilled to be exploring this new…
Today is the 8th of November 1996, and we’re thrilled to be exploring this new…
Free to use , passive subdomain enumerator
https://ift.tt/vIFxb3c
Submitted October 16, 2025 at 06:29PM by Mparigas
via reddit https://ift.tt/JcmXkwB
https://ift.tt/vIFxb3c
Submitted October 16, 2025 at 06:29PM by Mparigas
via reddit https://ift.tt/JcmXkwB
yup.gr
yup.gr | Random Tools
A collection of free, tools focused on security and convenience, including SSL validation, Base64 encoding, and more.
Exploiting browser cache smuggling with COM Hijacking and steganography
https://ift.tt/8nL6MXw
Submitted October 17, 2025 at 02:18AM by not_wet_now
via reddit https://ift.tt/xHsGlQA
https://ift.tt/8nL6MXw
Submitted October 17, 2025 at 02:18AM by not_wet_now
via reddit https://ift.tt/xHsGlQA
Medium
Revisiting Browser Cache Smuggling
I recently came across an article detailing a campaign using browser cache smuggling and ClickFix to deliver malware to a system. I found…
Sharing a resource I wish I’d had earlier in my InfoSec career
http://www.cyops.com.au
Submitted October 17, 2025 at 10:15AM by Info-Raptor
via reddit https://ift.tt/ZojvEw0
http://www.cyops.com.au
Submitted October 17, 2025 at 10:15AM by Info-Raptor
via reddit https://ift.tt/ZojvEw0
CyOps Consulting
Trusted Cybersecurity Advisory Services in Australia | CyOps Consulting
Cyops Consulting provides trusted cybersecurity advisory services in Australia, leveraging over 25 years of experience in federal government and defence. Our expert team is dedicated to transforming organisational risk into resilience, ensuring your security…
How I Reversed Amazon's Kindle Web Obfuscation Because Their App Sucked
https://ift.tt/wF1WJsj
Submitted October 17, 2025 at 12:36PM by AlmondOffSec
via reddit https://ift.tt/JQaGCKV
https://ift.tt/wF1WJsj
Submitted October 17, 2025 at 12:36PM by AlmondOffSec
via reddit https://ift.tt/JQaGCKV
Cats with power tools
How I Reversed Amazon's Kindle Web Obfuscation Because Their App Sucked
As it turns out they don't actually want you to do this (and have some interesting ways to stop you)
macOS Shortcuts for Initial Access
https://ift.tt/DmqP0xZ
Submitted October 18, 2025 at 06:31PM by SkyFallRobin
via reddit https://ift.tt/tAuBTnP
https://ift.tt/DmqP0xZ
Submitted October 18, 2025 at 06:31PM by SkyFallRobin
via reddit https://ift.tt/tAuBTnP
Medium
macOS Shortcuts for Initial Access
Check my other posts & tools MeetC2 & AWS XRayC2..
Notice: Google Gemini AI's Undisclosed 911 Auto-Dial Bypass – Logs and Evidence Available
https://ift.tt/vcdI23G
Submitted October 18, 2025 at 10:42PM by caveman1100011
via reddit https://ift.tt/hlA3MUZ
https://ift.tt/vcdI23G
Submitted October 18, 2025 at 10:42PM by caveman1100011
via reddit https://ift.tt/hlA3MUZ
Internet Archive
Gemini 911 Evidence FINAL : Anon : Free Download, Borrow, and Streaming : Internet Archive
Complete evidence package documenting Google Gemini AI autonomously initiating a 911 emergency call despite explicit user refusal on October 12,...
CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM
https://ift.tt/EWbVqfT
Submitted October 19, 2025 at 05:24PM by Steve_Dobbs_001
via reddit https://ift.tt/t7abJDf
https://ift.tt/EWbVqfT
Submitted October 19, 2025 at 05:24PM by Steve_Dobbs_001
via reddit https://ift.tt/t7abJDf
Ameeba Exploit Tracker - Tracking CVEs, exploits, and zero-days for defensive cybersecurity research.
CVE-2025-8941: Critical Privilege Escalation Vulnerability in Linux-PAM - Ameeba Exploit Tracker
Overview The Common Vulnerabilities and Exposures system recently identified an alarming flaw with the ID CVE-2025-8941, affecting the Pluggable Authentication Modules (PAM) in Linux operating systems. This vulnerability has significant implications, particularly…
DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes into Antivirus's Operating Folder
https://ift.tt/VDgIa4h
Submitted October 19, 2025 at 07:21PM by Cold-Dinosaur
via reddit https://ift.tt/Vljo407
https://ift.tt/VDgIa4h
Submitted October 19, 2025 at 07:21PM by Cold-Dinosaur
via reddit https://ift.tt/Vljo407
Zerosalarium
DefenderWrite: Abusing Whitelisted Programs for Arbitrary Writes
DefenderWrite tool that helps find programs whitelisted by Antivirus and exploits these programs to write arbitrary files into the Antivirus's folder
F5 Data Breach: What Happened and How It Impacts You
https://ift.tt/vAGZDSJ
Submitted October 19, 2025 at 09:02PM by digitalgiant01
via reddit https://ift.tt/IfBOcla
https://ift.tt/vAGZDSJ
Submitted October 19, 2025 at 09:02PM by digitalgiant01
via reddit https://ift.tt/IfBOcla
My Data Breach Attorney
F5 Data Breach | Trusted Data Breach Lawyers
Impacted by the F5 data breach? You may be ennoscriptd to legal compensation. My Data Breach Attorney can help protect your rights.
How a fake AI recruiter delivers five staged malware disguised as a dream job
https://ift.tt/DhIYmTB
Submitted October 20, 2025 at 05:06PM by shantanu14g
via reddit https://ift.tt/N9OefUa
https://ift.tt/DhIYmTB
Submitted October 20, 2025 at 05:06PM by shantanu14g
via reddit https://ift.tt/N9OefUa
Medium
How a fake AI recruiter delivers five staged malware disguised as a dream job
Overview
Tunneling WireGuard over HTTPS using Wstunnel
https://ift.tt/aptBOzK
Submitted October 20, 2025 at 11:07PM by 0bs1d1an-
via reddit https://www.reddit.com/r/netsec/comments/1obogco/tunneling_wireguard_over_https_using_wstunnel/?utm_source=ifttt
https://ift.tt/aptBOzK
Submitted October 20, 2025 at 11:07PM by 0bs1d1an-
via reddit https://www.reddit.com/r/netsec/comments/1obogco/tunneling_wireguard_over_https_using_wstunnel/?utm_source=ifttt
Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
https://ift.tt/j4B7YzV
Submitted October 21, 2025 at 01:14AM by Prior-Penalty
via reddit https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/?utm_source=ifttt
https://ift.tt/j4B7YzV
Submitted October 21, 2025 at 01:14AM by Prior-Penalty
via reddit https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/?utm_source=ifttt
CVE-2025-8078: ZYXEL Remote Code Execution via CLI Command Injection
https://ift.tt/bWekTsn
Submitted October 21, 2025 at 11:07AM by Advanced_Rough8330
via reddit https://ift.tt/RUmZYdi
https://ift.tt/bWekTsn
Submitted October 21, 2025 at 11:07AM by Advanced_Rough8330
via reddit https://ift.tt/RUmZYdi
Rainpwn
CVE-2025-8078: Remote Code Execution via CLI Command Injection
An undocumented parameter of the "web-auth" command could allow an authenticated attacker to execute commands remotely due to improper input sanitization, potentially resulting in full device compromise.
CVE-2025-9133: ZYXEL Configuration Exposure via Authorization Bypass
https://ift.tt/D6F7h0n
Submitted October 21, 2025 at 11:07AM by Advanced_Rough8330
via reddit https://ift.tt/BtHJrea
https://ift.tt/D6F7h0n
Submitted October 21, 2025 at 11:07AM by Advanced_Rough8330
via reddit https://ift.tt/BtHJrea
Rainpwn
CVE-2025-9133: Configuration Exposure via Authorization Bypass
A vulnerability in the zysh-cgi component of the USG/ATP Series allows a low-privileged, semi-authenticated attacker to access the device’s configuration, bypassing authorization controls. This issue arises due to missing authorization checks and an incomplete…